Privacy at a Glance
We believe in radical transparency. Here is a summary of how we handle your data, optimized for Google Play and Apple App Store requirements.
| Data Category | Examples | Usage Purpose | Encryption |
|---|---|---|---|
| Identity | Name, Phone Number | Authentication & Booking | TLS 1.3 / AES-256 |
| Device | Device ID, OS Type | Push Notifications | TLS 1.3 |
| Performance | Crash Logs, Latency | App Quality (Sentry) | Anonymized |
| Financial | Booking Transactions | Legal Compliance | Secure DB |
Account & Data Deletion
In accordance with Google Play User Data policies, we provide two mandatory pathways for users to delete their accounts and all associated data.
🇺🇿 O'zbekcha
- Ilovada: Profil → Akkauntni o'chirish.
- Veb: admin@lemon-tour.uz manziliga so'rov yuboring.
- Natija: Barcha shaxsiy ma'lumotlar o'chiriladi.
🇷🇺 Русский
- В приложении: Профиль → Удалить аккаунт.
- Веб: Отправьте запрос на admin@lemon-tour.uz.
- Результат: Все личные данные будут удалены.
🇺🇸 English
- In-App: Profile → Delete Account.
- Web: Email request to admin@lemon-tour.uz.
- Result: Permanent removal of all identity data.
Data Retention Policy
Standard Retention: We retain your personal data only as long as your account is active. Upon deletion, data is removed from production databases within 24 hours.
Legal Retention Exceptions: In compliance with the laws of the Republic of Uzbekistan, we may retain transaction records (booking history) for up to 5 years strictly for tax auditing, fraud prevention, and legal defense. This data is isolated and never used for marketing.
Security Architecture
- Encryption in Transit: All communications between the Lemon Tour app and our servers use TLS 1.3 encryption.
- Data at Rest: Personal data is stored on Supabase (PostgreSQL) using AES-256 volume-level encryption.
- Access Control: We implement Row Level Security (RLS) to ensure users can only access their own data.
- Infrastructure: Hosted on ISO 27001 certified data centers.
Third-Party Partners
We do not sell your data. We share only necessary metadata with the following verified processors:
- Telegram: For passwordless OAuth authentication.
- Supabase: For secure database hosting and storage.
- Sentry: For real-time error tracking and performance monitoring.
- Expo (EAS): For delivering push notification services.
Legal & Contact
Official Developer: Bekhruz Tursunbaev
Entity: Lemon Tour LLC (Registration #30658421)
Address: Chilanzar 17, Tashkent, Uzbekistan
Primary Support: admin@lemon-tour.uz
Technical Lead: dev@lemon-tour.uz
Phone: +998 99 838 99 21